FB pixel

Unit 42 finds attacks targeting Google-synced passkeys on Windows

Research targets cloud synchronization and device trust rather than the cryptography underlying passkeys
Unit 42 finds attacks targeting Google-synced passkeys on Windows
 

Researchers at Palo Alto Networks’ Unit 42 have identified three attacks against Google Password Manager’s synced passkeys on Windows, highlighting implementation risks in cloud-synchronized passkeys rather than weaknesses in passkey cryptography.

Unit 42 says the attacks exploit Google’s device trust, onboarding, and cloud authenticator implementation.

The researchers describe them as Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, with each targeting a different assumption about how synced passkeys are protected.

Pass-ta-key targets the device identity key that tells Google’s cloud authenticator that the request is coming from a trusted computer.

According to the researchers, malware running with user privileges can use wrapped key material stored in the local passkey state to generate a valid authentication request.

The attack produces a WebAuthn authentication assertion without the user verification (UV) flag.

Unit 42 found different outcomes among the services tested. For instance, GitHub rejected the attack because the required UV signal was absent. But eBay accepted the assertion despite requesting user verification.

eBay subsequently changed its implementation to validate the flag correctly, according to the researchers.

Silver Pass-ta-key overcomes that limitation.

Unit 42 says malware can force Chrome to re-onboard the device and register a new key that cloud authenticator treats as evidence that the user completed Windows Hello verification.

This can allow the attacker to produce assertions with the UV flag set without reproducing the user’s biometric or PIN.

Golden Pass-ta-key targets the security domain secret (SDS), which Unit 42 describes as a 32-byte symmetric master secret used to protect the private keys.

The researchers found the SDS displayed in plaintext in Chrome’s FIDO diagnostic logs during registration with Google’s cloud authenticator.

Google removed the value from those logs after Unit 42 reported the issue. But the researchers say Chrome still receives the SDS during device enrollment.

Pass-ta-key and Silver Pass-ta-key rely on cloud authenticator to produce valid assertions using credentials associated with the victim. But Golden Pass-ta-key allows the attacker to obtain the private keys in a portable form.

Unit 42’s findings do not show that an attacker can break public key cryptography passkeys.

The researchers do not extract a private key from the public key stored by a website, forge a signature without access to trusted key material, or identify a weakness in the WebAuthn challenge response protocol.

The attacks exploit systems responsible for storing, synchronizing, and using passkey credentials. Unit 42 says the findings expose gaps between the security assumptions around passkeys and their implementation.

FIDO Alliance has pushed back against broad claims that attacks involving compromised browsers or endpoints mean passkeys themselves are broken.

The findings do not show that passkeys or WebAuthn cryptography are broken. Instead, they target the systems responsible for storing, synchronizing and presenting passkey credentials on compromised endpoints. The research reinforces FIDO Alliance’s longstanding position that organizations should evaluate both the security of passkey providers and the devices on which synchronized credentials are stored, particularly for higher-assurance use cases.

Related Posts

Article Topics

 |   |   | 

Latest Biometrics News

 

Digital and trust infrastructure investments unlock value of identity

As the role of digital identity in society evolves and biometrics increasingly form the foundation of trust in remote interactions,…

 

Listen: How age assurance platforms earn trust

The world has more or less decided that some online services should be age-restricted. The question now is, how to…

 

Sri Lanka sets Q4 target for SL-UDI rollout

Sri Lanka is preparing to issue its first production digital identities next quarter, beginning a phased rollout of the country’s…

 

Madagascar strengthens trust architecture for national digital ID

Madagascar is strengthening the legal, institutional and technical foundations of its national digital identity program, introducing new cybercrime legislation as…

 

Cybastion backs Cameroon digital sovereignty with $75M infrastructure project

Cybastion has committed $75 million to fund the construction of digital infrastructure in Cameroon, including a data center and an…

 

Co-Develop, Caribou outline governance blueprint for DPI adoption

Digital public infrastructure (DPI) programs have grown to include more than 100 countries globally. Recognizing this expansion, Co-Develop and Caribou…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events